Based on best practices, which types of accounts should be disabled for interactive login?
A.
Local accounts
B.
Administrator accounts
C.
Console accounts
D.
Service accounts
The Answer Is:
D
This question includes an explanation.
Explanation:
Comprehensive and Detailed Step-by-Step Explanation:
Service accountsare used by applications or systems to perform automated tasks and shouldnot be allowed for interactive login, as they present security risks if compromised.
Service Accounts (Correct Answer – D)
Used for running background tasks (e.g., database services, scheduled jobs).
Should have minimal permissions and be denied interactive logins.
Example:A compromised service account with interactive login could allow attackers to gain system access.
Local Accounts (Incorrect – A)
Local administrator accounts should be restricted but may still be required for some systems.
Administrator Accounts (Incorrect – B)
Should be restricted, but disabling them entirely could lock out system management.
Console Accounts (Incorrect – C)
Console access is sometimes needed for system recovery and troubleshooting.
[References:, ISACA CISA Review Manual, NIST 800-63B (Digital Identity Guidelines), CIS (Center for Internet Security) Best Practices, , , ]
CISA PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 75% Discount on All Products,
Use Coupon: "ac75sure"